CVE-2023-45195

Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote attacker to enumerate or access systems the attacker would not otherwise have access to. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.4.
CVSS

No CVSS.

Configurations

No configuration.

History

21 Nov 2024, 08:26

Type Values Removed Values Added
References () https://github.com/adminerevo/adminerevo/pull/102/commits/18f3167bbcbec3bc746f62db72e016aa99144efc - () https://github.com/adminerevo/adminerevo/pull/102/commits/18f3167bbcbec3bc746f62db72e016aa99144efc -

25 Jun 2024, 12:24

Type Values Removed Values Added
Summary
  • (es) Adminer y AdminerEvo son vulnerables a SSRF a través de campos de conexión de base de datos. Esto podría permitir que un atacante remoto no autenticado enumere o acceda a sistemas a los que de otra manera el atacante no tendría acceso. Adminer ya no es compatible, pero este problema se solucionó en AdminerEvo versión 4.8.4.

24 Jun 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-24 22:15

Updated : 2024-11-21 08:26


NVD link : CVE-2023-45195

Mitre link : CVE-2023-45195

CVE.ORG link : CVE-2023-45195


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)